CyberRota Analysis
AI-GeneratedThe GeoDirectory WordPress plugin prior to version 2.8.168 is vulnerable due to inadequate access controls on its user-search functionality, permitting any authenticated user with Contributor-level access or higher to access the email addresses of all registered users, including administrators. This exposure could lead to privacy breaches and targeted phishing attacks. WordPress site administrators and security teams should prioritize this vulnerability to protect user data and maintain compliance with data protection regulations.
Original NVD Description
The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated user with Contributor-level access or higher to retrieve the email addresses of all registered users, including administrators.